Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Military & National Security Law
  3. National Security
  4. Cybersecurity Defense
  5. National Cybersecurity Compliance

Loading...

Cybersecurity Defense

National Cybersecurity Compliance

Which law governs cybersecurity?

The law on information security; a separate cybersecurity law has not yet been adopted.

How are subjects divided into categories?

The first — state bodies and enterprises, the second — electronic communication companies, the third — private legal entities; the list is approved by the government.

What is a network sensor?

A hardware and software means for monitoring network traffic — to detect an incident.

What is required when an incident occurs?

The subject identifies the incident with a network sensor and immediately notifies the relevant response team; the team’s instructions are binding.

4 min·...

The Current Framework and the Purpose of the Law

Cybersecurity in Georgia is governed today by the law on information security — a separate cybersecurity law has not yet been adopted, and this law is the operating regime. Its purpose is to promote effective information security protection, establish the rights and duties of the public and private sectors, and define the mechanisms of state control. The framework covers critical information systems and their subjects and is the legal foundation of critical infrastructure protection obligations.

Key Concepts and Categories of Subjects

Article 2 defines the key concepts: information security protects the access, integrity, authentication, confidentiality and continuous operation of information and systems; a cyberattack uses an electronic device or network to violate the integrity of systems or obtain information unlawfully; a computer incident violates the confidentiality, integrity or availability of information. A critical information system is one whose continuous functioning is important for defense, economic security, state government or society. Subjects fall into three categories: the first — state and municipal bodies and state enterprises created with more than 50% state participation; the second — electronic communication companies; the third — private legal entities. The list is approved by the government on the proposal of the Ministry of Justice, agreed with the defense and interior ministries and the State Security Service.

The perimeter of the most stringent duties is not fixed inside the law itself: the categories of critical information system subjects are determined by decree of the Government of Georgia — the first category covers state and municipal bodies and state enterprises, the second electronic communications companies, and the third other private-law legal entities. Whether an organisation falls inside the regime is therefore checked against the current decree, not against the statute alone.

Scope, Exclusions and the Security Policy

Under Article 3, the law applies to the subject and to organizations connected with it through employment, internship or contract. In compiling the list, the severity of disruption, expected economic damage, the necessity of the service, the number of users and the subject’s finances are considered. The law does not apply to the media, publishers’ editorial offices, scientific, educational, religious and social organizations and political parties; any legal entity may voluntarily assume these obligations. A commercial bank that is not a subject follows National Bank rules. The law does not affect freedom of information and personal data norms.

Under Article 4, the subject must adopt internal-use rules defining its information security policy. The policy must satisfy the minimum requirements, established by taking into account the standards of the International Organization for Standardization, the US National Institute of Standards and Technology, and the Information Systems Audit and Control Association. The adopted rules are submitted for review: first- and second-category subjects — to the Operative-Technical Agency, the third — to the Digital Governance Agency, and the defense sector — to the Cybersecurity Bureau. All three bodies analyze the documents and issue binding instructions to cure defects.

The Incident Response System

Under Article 8, incident management in cyberspace is exercised by the computer incident response team of the Digital Governance Agency. Priority threats include a cyberattack threatening human life and health, state interests or the country’s defense capability, an attack on a subject’s systems, a threat to financial resources or property, and any other sufficiently serious action. Under Article 10, the subject identifies incidents using a network sensor and immediately notifies the relevant response team. The team examines the incident and issues binding instructions, to which the subject must respond within a reasonable period. In defense, incidents are managed by the Cybersecurity Bureau’s team, with access to the sensor and the subject’s assets; the response period for its instructions is at most 1 month. The teams create a unified information-sharing platform.

Liability for Violations

Article 10-8 establishes administrative sanctions: failure to notify the identification of a computer incident, failure to fulfill binding instructions, or failure to submit information on the measures taken entails, for a first-category subject, a warning or a fine of 5 000 GEL, and repetition of the same violation within 1 year — a fine of 10 000 GEL. The same sanctions apply to third-category subjects. The operator’s specific obligations — audits, appointment of a manager and a specialist, asset management — are established by other articles of the law and are discussed on a separate page.

Frequently Asked Questions

Which law regulates cybersecurity in Georgia?

The law on information security; a separate cybersecurity law has not yet been adopted, and the operating regime rests on this law.

Who are the three regulators?

For the first and second categories — the Operative-Technical Agency; for the third — the Digital Governance Agency; for the defense sector — the Cybersecurity Bureau.

Whom does the law not cover?

The media, publishers’ editorial offices, scientific, educational, religious and social organizations, and political parties.

What fine follows from concealing an incident?

A warning or a 5 000 GEL fine; in case of repetition — a 10 000 GEL fine.

How We Help on Legal.ge

On Legal.ge we help organizations determine their category and obligations, prepare the security policy and interact with the regulators. Contact our team on any issue of cybersecurity legislation.

Updated: ...

Find a Specialist

Professionals working in this field

Military & National Security Law LawyerMilitary & National Security Law Attorney